railiance-apps/manifests
tegwick c5546ac729
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
feat(informed-decision): claim decisions.coulomb.social as the approver origin
INFD-WP-0001-T07 has been blocked since 2026-09-08 on an OIDC redirect URI it
cannot publish without a real deployed origin, which in turn blocks key-cape's
KEY-WP-0013-T02. The operator assigned decisions.coulomb.social; DNS already
resolves to the cluster address.

Adds the Ingress + letsencrypt-prod certificate for the host and a placeholder
nginx backend, so the origin answers before the approver UI itself exists
(INFD-WP-0001-T08 is still gated on approval-engine and on intake INFD-IN-0003).
A redirect URI matches byte-exactly at /authorize, so a host that resolves but
does not complete a TLS handshake fails closed at first login and presents as a
rejected approval rather than a registration defect.

The Ingress carries one path rule on purpose: reuse-surface reported on
2026-07-07 that an Exact rule alongside a catch-all Prefix rule on the same host
was swallowed by the catch-all. That trap is worth avoiding on a host whose
entire purpose is exact-match redirect handling.

Dry-run clean against the live API; deliberately not applied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EJbh7o7UWF4tQ5jxygnNGu

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2072522@bnt-lap001
Assistant-Session: 46173adf-7302-4ede-99d6-963b61359928
2026-09-10 16:17:48 +02:00
..
cnpg-backup-readiness.yaml RAILIANCE-WP-0015: Option A CNPG logical backup coverage healthy 2026-07-22 18:00:48 +02:00
cnpg-option-a-backup.yaml RAILIANCE-WP-0016: finish unattended hybrid Option A backups 2026-07-22 20:34:24 +02:00
cnpg-option-a-netpol.yaml RAILIANCE-WP-0016: finish unattended hybrid Option A backups 2026-07-22 20:34:24 +02:00
coulomb-social-ingress.yaml Use websecure-only ingress for coulomb-social HTTP-01 2026-08-09 23:37:08 +02:00
forgejo-ingress.yaml Deploy Forgejo on railiance01 using gitea-charts/gitea 12.5.0 2026-07-03 21:28:37 +02:00
forgejo-mailer-externalsecret.yaml Fix Forgejo mailer ESO field mapping and token bootstrap env 2026-07-07 15:21:40 +02:00
forgejo-runner.yaml Fix in-cluster runner startup and readiness probes 2026-07-03 22:32:34 +02:00
forgejo-ssh-nodeport.yaml Deploy Forgejo on railiance01 using gitea-charts/gitea 12.5.0 2026-07-03 21:28:37 +02:00
informed-decision-ingress.yaml feat(informed-decision): claim decisions.coulomb.social as the approver origin 2026-09-10 16:17:48 +02:00
informed-decision-origin.yaml feat(informed-decision): claim decisions.coulomb.social as the approver origin 2026-09-10 16:17:48 +02:00
reuse-surface-runtime-externalsecret.yaml Deploy reuse-surface runtime secrets via OpenBao External Secrets 2026-07-07 22:34:34 +02:00
vergabe-teilnahme-ingress.yaml RAILIANCE-WP-0002 T05+T06 done: vergabe-teilnahme is live at https://vergabe-teilnahme.whywhynot.de 2026-05-19 19:46:49 +02:00